CVE-2018-7797
Last modified
CVE-2018-7797 is a vulnerability of currently unknown severity. A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module, EcoStruxure Power Monitoring Expert (PME) v9.0, EcoStruxure Energy Expert v2.0, and EcoStruxure Power SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module which could cause a phishing attack when redirected to a malicious site.. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module, EcoStruxure Power Monitoring Expert (PME) v9.0, EcoStruxure Energy Expert v2.0, and EcoStruxure Power SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module which could cause a phishing attack when redirected to a malicious site.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Ecostruxure Energy Expert | 1.3 |
| Schneider-Electric | Ecostruxure Energy Expert | 2.0 |
| Schneider-Electric | Ecostruxure Power Monitoring Expert | 8.2 |
| Schneider-Electric | Ecostruxure Power Monitoring Expert | 9.0 |
| Schneider-Electric | Ecostruxure Power Scada Operation | 8.2 |
| Schneider-Electric | Ecostruxure Power Scada Operation | 9.0 |
References
- http://www.securityfocus.com/bid/106277Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/106277Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7797?
How severe is CVE-2018-7797?
How do I fix CVE-2018-7797?
Are you affected by CVE-2018-7797?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
